Google · Google Chrome · CVE-2026-91719
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 153.0.8010.47
**Description**
Code injection in XML allows a remote attacker to bypass the web origin policy, which is a security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin, by using a crafted HTML page.
**Recommendations**
Update Google Chrome to version 153.0.8010.47 or later.